StudyToCert

All certifications / SSCP / Lessons

ISC2 SSCP Oct 2025 outline · Domain 7: Systems & application security

Malicious activity and indicators: beaconing, persistence, privilege escalation

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Detecting an attack usually means noticing behavior, not malware files. Indicators of compromise (IoCs) are artifacts that suggest a system has been breached: known bad IP addresses and domains, file hashes, unusual registry keys, strange processes or log entries. Indicators of attack focus on behaviors in progress. As an SSCP you will review alerts and logs, so you need to recognize the common patterns of attacker activity after initial access.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SSCP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SSCP study plan